Executive brief
Metasoft MetaCRM, a customer relationship management platform, contains a security flaw that allows users to upload unauthorized files to the server. An attacker could use this to upload malicious scripts, potentially leading to unauthorized access to company data or disruption of business operations. The vulnerability is publicly known, and the manufacturer has not yet provided a fix.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in Metasoft MetaCRM 6.4.0 within the 'develop/systparam/softlogo/upload.jsp' file. The application fails to properly validate file types or extensions during the upload process. A remote attacker with low-level privileges can exploit this by sending a specially crafted request to upload a malicious file (such as a JSP web shell). Successful exploitation could allow for remote code execution (RCE) on the underlying server. As of the advisory date, the vendor has not responded to disclosure attempts, and no patch is available.
Affected products
- Metasoft 美特软件 MetaCRM 6.4.0
Timeline
- 2026-06-01: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-06-01: advisory: CVE-2026-10205 published.